{
  "id": "CVE-2016-10174",
  "url": "https://spydr.io/cve/CVE-2016-10174",
  "published": "2017-01-30T04:59:00.157Z",
  "modified": "2026-06-17T00:39:12.707Z",
  "score": 9.8,
  "severity": "critical",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.83328,
  "epss_percentile": 0.99675,
  "exploited": true,
  "kev": {
    "added": "2022-03-25",
    "due": "2022-04-15",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2016-10174"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "netgear"
  ],
  "products": [
    "netgear d6100 firmware",
    "netgear d7000 firmware",
    "netgear d7800 firmware",
    "netgear jnr1010v2 firmware",
    "netgear jnr3300 firmware",
    "netgear jwnr2010v5 firmware",
    "netgear r2000 firmware",
    "netgear r6100 firmware",
    "netgear r6220 firmware",
    "netgear r7500 firmware",
    "netgear r7500v2 firmware",
    "netgear wndr3700v4 firmware",
    "netgear wndr3800 firmware",
    "netgear wndr4300 firmware",
    "netgear wndr4300v2 firmware",
    "netgear wndr4500v3 firmware",
    "netgear wndr4700 firmware",
    "netgear wnr1000v2 firmware",
    "netgear wnr1000v4 firmware",
    "netgear wnr2000v3 firmware"
  ],
  "cwes": [
    "CWE-120"
  ],
  "description": "The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 9.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://kb.netgear.com/000036549/Insecure-Remote-Access-and-Command-Execution-Security-Vulnerability",
      "tags": [
        "Vendor Advisory"
      ]
    },
    {
      "url": "http://seclists.org/fulldisclosure/2016/Dec/72",
      "tags": [
        "Exploit",
        "Mailing List",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.securityfocus.com/bid/95867",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000.txt",
      "tags": [
        "Exploit",
        "Technical Description",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.exploit-db.com/exploits/40949/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://www.exploit-db.com/exploits/41719/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-10174",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2016-10174",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
